HomeSecurityMicrosoft Exchange: Critical vulnerability allows access to other users' mailboxes

Microsoft Exchange: Critical vulnerability allows access to other users' mailboxes

Microsoft has released emergency security updates to address a serious vulnerability in Exchange Server Microsoft that could allow an attacker to escalate privileges under certain circumstances. The vulnerability, tracked as CVE-2026-96940 , is rated 8.8 on the CVSS scoring system, indicating its severity.

Article Image: Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

The vulnerability relates to weak authorization in Microsoft Exchange Server, allowing an authenticated attacker to escalate privileges over a network. According to Microsoft's announcement on October 2, 2026, an authenticated attacker could exploit this vulnerability to gain unauthorized access to the mailboxes of other users within the same organization and read email messages and attachments.

However, the vulnerability does not allow access between different tenants, thus limiting the scope of exploitation.

Microsoft has already deployed a “relevant fix” for Exchange Online , addressing the issue for Exchange Online customers. This means that Exchange Online customers do not need to take any additional action to protect themselves. However, users of affected on-premises Microsoft Exchange Server products are advised to install the updates to stay protected.

See also: Azerbaijani energy company suffered repeated Microsoft Exchange exploit

Affected versions include Microsoft Exchange Server Subscription Edition RTM, Microsoft Exchange Server 2016 Cumulative Update 23, and Microsoft Exchange Server 2019 versions 14 and 15.

Microsoft Exchange vulnerability - SecNews.gr

The discovery and reporting of the vulnerability is attributed to Microsoft researcher Jan Mitchell. While there is no evidence that the vulnerability has been exploited in the field, Microsoft has rated it with a “Most Likely Exploitable” rating. This makes it imperative for users to move quickly to apply the fixesin order to protect themselves from potential attacks.

See also: Microsoft Exchange Online is marking legitimate emails as phishing

The vulnerability disclosure comes just days after Symantec that Warlock was exploiting multiple vulnerabilities in Microsoft SharePoint to deploy its eponymous ransomware in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The development underscores the ongoing threat organizations face from cybercriminals exploiting vulnerabilities in popular software.

Microsoft Exchange: Reminder for constant vigilance

The Microsoft Exchange vulnerability CVE-2026-96940 is a reminder of the need for continued vigilance and prompt response to security updates. Organizations using on-premises installations of Microsoft Exchange Server must ensure that their systems are up-to-date with the latest security patches. Failure to do so can lead to serious data breaches, with potential repercussions for the organizations' reputation and financial stability.

See also: ToddyCat targets Microsoft Exchange Servers via ProxyLogon

This vulnerability also highlights the importance of collaboration between security researchers and software vendors to quickly identify and fix security vulnerabilities. Early identification and immediate action can significantly reduce the risk of exploitation by malicious actors. Users and system administrators must stay informed about the latest developments in cybersecurity and implement best practices to protect their systems.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS